Daily Cyber & AI Briefing with Michael Housch. This episode was published automatically and includes the assembled audio plus full transcript. TranscriptToday’s cyber and AI risk landscape is in a state of rapid evolution, with several significant developments shaping the way organizations need to think about security, governance, and resilience. Over the next several minutes, I’ll walk through the most pressing issues facing CISOs, risk executives, and security teams today, drawing on recent high-profile incidents, emerging best practices, and the shifting dynamics of both cybercrime and global AI regulation. Let’s start with one of the more unusual stories in recent memory—an open feud between two of the world’s most notorious ransomware gangs. The group known as ShinyHunters has publicly claimed responsibility for hacking the dark web leak site operated by their rivals, the Clop ransomware gang. Multiple sources have confirmed the attack, which disrupted Clop’s operations and exposed the inner workings of their infrastructure. Why does this matter to security leaders? For one, it’s a stark reminder that even the most sophisticated criminal organizations are vulnerable to the same types of attacks they inflict on others. But beyond that, this kind of infighting introduces a new layer of volatility into the ransomware ecosystem. When criminal groups turn on each other, we often see unpredictable shifts in tactics, sudden data dumps, and spillover effects that can impact legitimate organizations. For example, data exfiltrated in these feuds may end up being released publicly, increasing the risk of exposure for companies that have previously paid ransoms or been targeted by either group. The lesson here is that the threat landscape isn’t just shaped by external actors targeting businesses—it’s also influenced by the dynamics within the cybercriminal community itself. For defenders, this means staying alert to changes in ransomware group behavior, monitoring for unexpected data leaks, and preparing for the possibility that your organization could be caught in the crossfire of these criminal disputes. Shifting gears, we’re seeing continued evidence that supply chain attacks remain one of the most persistent and challenging risks in cybersecurity. CrowdSec, a well-known open-source security vendor, recently confirmed that its source code was stolen in a supply chain breach. This incident underscores the ongoing vulnerability of third-party software dependencies—especially in open-source ecosystems, where code is often reused and integrated across countless organizations. For CISOs, the implications are clear: it’s no longer enough to trust that a reputable vendor or open-source project is inherently secure. Rigorous vetting of software components, continuous monitoring for unauthorized changes, and robust incident response plans are now essential elements of any effective security program. The CrowdSec breach is a reminder that even security vendors themselves are not immune to these risks, and that the downstream impacts of a single compromise can ripple across entire industries. In a related vein, attackers are getting more creative in their attempts to infiltrate open-source communities. Members of the Rust programming language team, along with maintainers of several popular Rust crates, have been targeted in a sophisticated social engineering campaign involving video calls. The attackers used direct communication to try and compromise identities, with the apparent goal of injecting malicious code into widely used packages. This is a clear example of how the human element remains a critical vulnerability, even in technically robust environments. Social engineering isn’t just about phishing emails anymore—it’s evolving to include more personalized, high-touch tactics that can be difficult to detect. For developer communities, this highlights the importance of strong identity verification, secure communication practices, and a culture of vigilance against manipulation. It also points to the need for layered defenses that combine technical controls with ongoing security awareness training. While these technical and human risks continue to evolve, we’re also witnessing a surge in global activity around AI governance. Just recently, President Trump and President Xi Jinping met to discuss the future of global AI regulation. This high-profile meeting signals that AI risk management has become a top-tier geopolitical issue, with significant implications for international regulatory approaches, data sovereignty, and cross-border collaboration. For security executives, this development is more than just a headline. It foreshadows a period of increased scrutiny on AI-enabled systems, especially for multinational organizations operating across multiple jurisdictions. We can expect to see new compliance requirements, tighter controls on data flows, and a growing emphasis on transparency and accountability in AI development and deployment. Adding to this, a fellow from Chatham House provided expert testimony to the UK Parliament on the global risks and governance challenges posed by AI. The session emphasized the need for coordinated international frameworks and highlighted the complexity of managing AI risks across different legal and regulatory environments. This is a space that’s moving quickly, and organizations will need to stay agile to keep up with new standards and expectations as they emerge. One practical response to these challenges is the development and adoption of specialized platforms designed to address data sovereignty and AI security. Seclore, for example, has launched its ARMOR platform, which aims to help organizations enforce data residency, control access, and secure sensitive information within AI workflows. As regulatory and customer demands for data localization and AI transparency continue to grow, solutions like this are becoming increasingly relevant. For CISOs, the message is clear: data governance and AI security need to be integrated into every stage of the technology lifecycle, from initial design through to deployment and ongoing management. Industry guidance is also evolving to reflect these new realities. Bulwark, a security solutions provider, has recently outlined key cybersecurity priorities for organizations integrating AI into their operations. Their focus areas include securing AI models against tampering, managing data privacy risks, and ensuring compliance with a rapidly changing regulatory landscape. This reflects a broader industry shift toward embedding security and governance directly into the AI development process, rather than treating them as afterthoughts. One area where this is especially relevant is marketing. As AI becomes more deeply integrated into customer engagement strategies, there’s a growing need for frameworks that ensure transparency, accountability, and risk assessment in AI-driven campaigns. A new governance framework for AI in marketing has been proposed, emphasizing the importance of collaboration between marketing, security, and compliance teams. The goal is to mitigate reputational and regulatory risks before they materialize, rather than reacting after the fact. Turning our attention to cloud security, Unit 42 has detailed how AWS uses managed policies to detect and neutralize compromised IAM credentials. By automating controls and continuously monitoring for suspicious activity, AWS is able to reduce the window of exposure when credentials are compromised. This is a powerful example of how cloud providers and customers can work together to enhance security, but it also highlights the need for organizations to understand and implement shared responsibility models. Automated controls, rapid response capabilities, and continuous monitoring are now table stakes for any effective cloud security strategy. To build on that, CloudSEK has provided a comprehensive overview of cloud security fundamentals, including the components, risks, and responsibilities involved. As cloud adoption accelerates across industries, it’s essential for organizations to understand where their responsibilities begin and end, and to implement best practices for securing cloud environments. This includes everything from identity and access management, to encryption, to monitoring for misconfigurations and unauthorized activity. Financial services are another sector where AI governance and compliance are taking center stage. Persistent Systems has achieved a specialization with Databricks to support governed AI initiatives in banking, financial services, and insurance. This move reflects the sector’s focus on embedding governance and compliance into AI projects from the outset, particularly when dealing with sensitive data and stringent regulatory requirements. For organizations in highly regulated industries, this is a model worth emulating—prioritizing governance as a foundational element of any AI initiative. Threat intelligence remains a cornerstone of effective cybersecurity. Analytics Insight has highlighted the value of integrating threat intelligence into security operations, emphasizing proactive monitoring, information sharing, and actionable insights. By leveraging threat intelligence, organizations can enhance their ability to detect and respond to emerging threats, often before they escalate into full-blown incidents. This proactive approach is especially important in today’s environment, where threat actors are constantly evolving their tactics and looking for new ways to exploit vulnerabilities. Stepping back to look at the bigger picture, several strategic implications emerge from these developments. First, supply chain and open-source software risks remain a critical vulnerability for organizations of all sizes. Proactive monitoring, rigorou